| CVE-2023-25703 | WordPress Meta slider and carousel with lightbox plugin <= 1.6.2 - Broken Access Control vulnerability | WP OnlineSupport, Essential Plugin | Meta slider and carousel with lightbox | Medium | 5.3 | 2024-12-09 11:31:31 | Deep Dive |
| CVE-2024-4633 | Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.2.1- Authenticated (Author+) Stored Cross-Site Scripting | averta | Depicter — Popup & Slider Builder | Medium | 6.4 | 2024-12-06 13:45:20 | Deep Dive |
| CVE-2024-5020 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-12-04 08:22:47 | Deep Dive |
| CVE-2024-52461 | WordPress Infinite Slider plugin <= 2.0.1 - Reflected Cross Site Scripting (XSS) vulnerability | Kinsta | Infinite Slider | High | 7.1 | 2024-12-02 13:49:05 | Deep Dive |
| CVE-2024-53749 | WordPress Post Carousel Slider for Elementor plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability | Plugin Devs | Post Carousel Slider for Elementor | Medium | 6.5 | 2024-12-01 21:21:51 | Deep Dive |
| CVE-2024-10896 | Logo Slider < 4.5.0 - Contributor+ Stored XSS | Unknown | Logo Slider | - | - | 2024-11-28 06:00:12 | Deep Dive |
| CVE-2024-10473 | Logo Slider < 4.5.0 - Author+ Stored XSS | Unknown | Logo Slider | - | - | 2024-11-28 06:00:05 | Deep Dive |
| CVE-2024-10886 | Tribute Testimonials – WordPress Testimonial Grid/Slider <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | boomdevs | Tribute Testimonials – WordPress Testimonial Grid/Slider | Medium | 6.4 | 2024-11-23 03:25:50 | Deep Dive |
| CVE-2024-51834 | WordPress Luzuk Slider plugin <= 0.1.5 - Stored Cross Site Scripting (XSS) vulnerability | luzuk Themes | Luzuk Slider | Medium | 6.5 | 2024-11-19 16:31:42 | Deep Dive |
| CVE-2024-51887 | WordPress NV Slider plugin <= 1.6 - Stored Cross Site Scripting (XSS) vulnerability | ryscript | NV Slider | Medium | 6.5 | 2024-11-19 16:31:15 | Deep Dive |
| CVE-2024-51896 | WordPress Magic Slider plugin <= 1.3 - Stored Cross Site Scripting (XSS) vulnerability | webvitaly | Magic Slider | Medium | 6.5 | 2024-11-19 16:31:10 | Deep Dive |
| CVE-2024-51925 | WordPress Testimonial Slider Shortcode plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability | Sazzad | Testimonial Slider Shortcode | Medium | 6.5 | 2024-11-19 16:30:56 | Deep Dive |
| CVE-2024-51932 | WordPress Kings Tab Slider plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | Saif | Kings Tab Slider | Medium | 6.5 | 2024-11-19 16:30:52 | Deep Dive |
| CVE-2024-52405 | WordPress B-Banner Slider plugin <= 1.1 - Arbitrary File Upload vulnerability | bikramjoshii | B-Banner Slider | Critical | 9.9 | 2024-11-16 21:50:29 | Deep Dive |
| CVE-2024-8985 | Social Proof (Testimonials) Slider <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via spslider-block Shortcode | kimberlynorris | Social Proof (Testimonial) Slider | Medium | 6.4 | 2024-11-13 02:02:30 | Deep Dive |
| CVE-2024-51763 | WordPress Team Showcase and Slider plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability | biplob018 | Team Showcase and Slider – Team Members Builder | High | 7.1 | 2024-11-09 09:27:37 | Deep Dive |
| CVE-2024-10667 | Content Slider Block – Create fully functional slider with Gutenberg block <= 3.1.5 - Authenticated (Contributor+) Post Disclosure | bplugins | Content Slider Block – Slide Through Text or Media Content | Medium | 4.3 | 2024-11-09 04:32:27 | Deep Dive |
| CVE-2024-8442 | Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Blog Widget | bdthemes | Prime Slider – Addons for Elementor | Medium | 6.4 | 2024-11-07 12:30:53 | Deep Dive |
| CVE-2024-43215 | WordPress Social Slider Feed plugin <= 2.2.2 - Broken Access Control vulnerability | creativemotion | Social Slider Feed | Medium | 4.3 | 2024-11-01 14:17:39 | Deep Dive |
| CVE-2024-47359 | WordPress Depicter plugin <= 3.2.2 - Broken Access Control vulnerability | averta | Depicter Slider | Medium | 5.3 | 2024-11-01 14:17:04 | Deep Dive |